Database/AI/ML frameworks & serving
NVIDIA DeepStream: crafted tensor dimensions in a YAML config trigger an integer overflow
Impact
Crafted tensor dimensions in a DeepStream YAML configuration file cause an integer overflow, which NVIDIA says may lead to denial of service, information disclosure or data tampering. DeepStream pipelines run on GPU nodes and are typically driven by config files that select models and tensor shapes, so a tenant or operator who can supply that config can crash the pipeline or read memory it should not reach. NVIDIA rates it 7.8 local with low privileges; the record does not claim code execution, so treat this as a memory-safety bug reachable from configuration rather than a confirmed RCE.
Who can reach it
Local, authenticated: a user or pipeline able to provide the DeepStream YAML configuration the process parses. No user interaction beyond the service loading the config.
What to do
Update DeepStream to the fixed version listed in NVIDIA bulletin 2026/5886 and restart the DeepStream pipelines; this is a software update and process restart, not node maintenance. Until then, restrict write access to DeepStream configuration files to trusted operators and do not accept tenant-supplied pipeline configs.
References
Related entries
- NVIDIA NeMo Speech: code injection from malicious input, no user interaction neededCVE-2026-65111 · NVIDIA NeMo SpeechHigh
- NVIDIA NeMo: a crafted model_config.yaml injects unsafe parameters into dataset loadingCVE-2026-65178 · NVIDIA NeMo (dataset-loading workflow, model_config.yaml parameter injection)High
- PyTorch (flatbuffer model parsing, torch::load / parse_and_initialize_mobile_module): MALICIOUS MODEL FILE TO MEMORYNCVD-2025-019-pytorch-flatbuffer-model-parsing · PyTorch (flatbuffer model parsing, torch::load / parse_and_initialize_mobile_module)High
- LangChain (Web Research Retriever): SSRFCVE-2024-3095 · LangChain (Web Research Retriever)High
- LangGraph MongoDB checkpoint and store: filter dicts allow MQL operator injection across tenantsCVE-2026-55253 · langgraph-checkpoint-mongodb / langgraph-store-mongodb (MongoDBSaver.list, MongoDBStore.search filters)High
- Kedro-Datasets PyTorchDataset: torch.load without weights_only executes code from .pt filesCVE-2026-62997 · kedro-datasets PyTorchDataset (kedro_datasets_experimental.pytorch)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.